{"id":"CVE-2025-5791","title":"users: `root` appended to group listings (CVE-2025-5791)","summary":"A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in th…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cvssSource":"vendor","cwe":"CWE-266","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4","trusted_profile_analyzer","openshift_sandboxed_containers 1.1"],"patched":["openshift_sandboxed_containers 1.1"],"published":"2025-01-15","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:17:35+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5791.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5791.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-5791"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2370001"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-5791"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5791"},{"url":"https://crates.io/crates/users"},{"url":"https://github.com/ogham/rust-users/issues/44"},{"url":"https://rustsec.org/advisories/RUSTSEC-2025-0040.html"},{"url":"https://access.redhat.com/errata/RHSA-2025:12359"},{"url":"https://github.com/ogham/rust-users"}],"tags":["csaf","vex","red-hat","osv","rust"],"epss":0.00197,"epssPercentile":0.09708,"aliases":["GHSA-m65q-v92h-cm7q","RUSTSEC-2025-0040"],"ecosystem":"rust","ingestedAt":"2026-07-16T18:59:42.811Z","slug":"CVE-2025-5791","body":"## Overview\n\nA flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.\n\n## Vendor advisories\n\n- **RHSA-2025:12359** · Red Hat · fixed in: Red Hat OpenShift sandboxed containers 1.1 · released 2025-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2025:12359)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Trusted Profile Analyzer · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Trusted Profile Analyzer · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-5791.json)\n\n**users: `root` appended to group listings** — rated Important by Red Hat. Released 2025-01-15, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat Trusted Profile Analyzer\n\nFixed:\n\n- Red Hat OpenShift sandboxed containers 1.1\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat Trusted Profile Analyzer\n\nNot affected:\n\n- Red Hat OpenShift sandboxed containers 1.1\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nA new release of Red Hat OpenShift sandboxed containers. https://access.redhat.com/errata/RHSA-2025:12359\n\n## Package advisory (CVE-2025-5791)\n\nAffected packages:\n\n- `users >= 0.8.0, <= 0.11.0`\n\nSource: https://osv.dev/vulnerability/GHSA-m65q-v92h-cm7q","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}